OpenSSL 4.0.3 released with high-severity security fixes
OpenSSL 4.0.3 is out as a security patch for the widely used cryptography and TLS toolkit. It fixes 14 CVEs, including one rated High severity, spanning DTLS, QUIC, X.509 processing and elliptic-curve operations. Users on OpenSSL 4.0 are advised to update.
- 14 CVEs fixed, one rated High severity
- CVE-2026-84783 is a use-after-free in the X.509 extension cache
- QUIC DoS flaws and timing side-channels in SM2 and EC fixed
- Also fixes a base64 BIO filter regression from OpenSSL 4.0
Read next
Software